PulseExploreJournal ClubDebatesTrendingResearchersJournals
Instagram
HomeExploreJournal ClubTrending
Synapse
⌘+K
Synapse
January 1, 20224 citationsOpen Access

Weight Perturbation as Defense against Adversarial Word Substitutions

View Full Paper
JXJianhan XuLLLinyang LiJZJiping Zhang

Key Points

Key points are not available for this paper at this time.

Abstract

The existence and pervasiveness of textual adversarial examples have raised serious concerns to security-critical applications. Many methods have been developed to defend against adversarial attacks for neural natural language processing (NLP) models.Adversarial training is one of the most successful defense methods by adding some random or intentional perturbations to the original input texts and making the models robust to the perturbed examples.In this study, we explore the feasibility of improving the adversarial robustness of NLP models by performing perturbations in the parameter space rather than the input feature space.The weight perturbation helps to find a better solution (i.e., the values of weights) that minimizes the adversarial loss among other feasible solutions.We found that the weight perturbation can significantly improve the robustness of NLP models when it is combined with the perturbation in the input embedding space, yielding the highest accuracy on both clean and adversarial examples across different datasets.

Ask AI
Helpful
Bookmark
Share
View Full Paper

Cite This Study

Xu et al. (2022) studied this question.

synapsesocial.com/papers/6a1c7832973ffece4bc3dd44https://doi.org/10.18653/v1/2022.findings-emnlp.523
Ask AI
Helpful
Bookmark
Share
View Full Paper